Latest Posts › Cybersecurity

Share:

Understanding DORA: Digital Operational Resilience Act Now in Effect for Financial Entities and ICT Service Providers

DORA, the first EU regulation designed to establish a unified and robust digital resilience standard for the financial sector, becomes directly applicable on January 17, 2025, introducing significant penalties and...more

NIS 2 Directive: Transposition Period is Up for EU Member States

As the national implementation deadline for the NIS 2 EU Directive is over, businesses in scope should ensure they will soon be ready to comply with the strengthened cybersecurity requirements....more

EU Enacts Broad Cybersecurity Requirements for Hardware and Software Products

On October 10, 2024, the EU Cyber Resilience Act ("CRA") was adopted by the Council of the European Union....more

UK-U.S. Data Bridge Allows Transfer of Personal Data From the United Kingdom to the United States

Beginning October 12, 2023, the UK-U.S. Data Bridge will allow UK companies to transfer personal data to the United States using the new EU-U.S. Data Privacy Framework....more

European Union and United States Reach New Agreement for Data Flow Across the Atlantic

On July 10, 2023, the EU Commission adopted its adequacy decision for the EU-U.S. Data Privacy Framework, concluding that the United States ensures an adequate level of protection for personal data transferred from the...more

China Issues Guidance on Filing of the Standard Contract for Cross-Border Transfers of Personal Information

On May 30, 2023, the Cyberspace Administration of China ("CAC") issued the "Guidance on Filing the Standard Contract for the Cross-Border Transfer of Personal Information" ("Guidance"), which took effect on June 1, 2023....more

CJEU Clarifies the Right to Compensation for GDPR Infringements Causing Non-Material Damage

In Short - The Situation: There has been uncertainty over the circumstances in which data subjects can claim compensation for "mere" infringement of their rights without specific evidence of harm. On May 4, 2023, the Court...more

China Finalizes Measures on the Standard Contract for Cross-Border Transfers of Personal Information

On February 24, 2023, the Cyberspace Administration of China ("CAC") issued the long-awaited Measures on the Standard Contract for Outbound Cross-Border Transfer of Personal Information ("Measures")....more

French Law Authorizes Insurability of "Cyber-Ransoms" Paid by Victims, Subject to Prompt Filing of Complaint

France's Orientation and Programming Law of the Ministry of the Interior ("LOMPI law"), published in the Official Journal of January 25, 2023, amends the insurance coverage of losses and damages paid in response to...more

Rising Global Regulation for Artificial Intelligence

Across multiple continents and industries, artificial intelligence ("AI") is a topic of intense focus by governments, research institutions, investors, and corporations—from start-ups to well-established industry players. As...more

EU Adopts Enhanced Legal Framework to Provide for High Common Level of Cybersecurity

The Council of the European Union ("EU") adopted a new Directive to strengthen cybersecurity and resilience across the Union. - Following the European Parliament's approval on November 10, 2022, the Council of the European...more

United States Signs Executive Order to Implement EU-U.S. Trans-Atlantic Data Privacy Framework

On October 7, 2022, President Biden signed an executive order on "Enhancing Safeguards for United States Signals Intelligence Activities," outlining the measures that the United States will take to implement its commitments...more

European Commission Proposes New Liability Rules on Products and AI

On September 28, 2022, the European Commission published two proposals—the Revised Product Liability Directive and the AI Liability Directive—aimed at adapting liability rules to the green and digital transition within the...more

European Commission Proposes Legislation Imposing New Cybersecurity Requirements on Digital Products

On September 15, 2022, the European Commission ("EU") published a proposal for a Cyber Resilience Act, the first EU-wide legislation introducing a single set of cybersecurity rules for hardware and software products placed in...more

UK Proposes New Standard Contractual Clauses for Data Transfers to Third Countries

EU and UK data protection rules each restrict transfers of personal data to third countries not regarded as having an adequate level of protection, such as the United States, China, Russia and India....more

Model Terms Demanded for Cloud Service Agreements with European Banks

An interest group of EU banks that was formed to assist European financial institutions with their use of public cloud technology recently suggested model terms for the compliant use of cloud technology. On May 17, 2021,...more

Regulating Artificial Intelligence: European Commission Launches Proposals

The Development: On 21 April 2021, the European Commission ("Commission") unveiled a proposal for a "Regulation laying down harmonized rules on Artificial Intelligence" ("AI Regulation"), which sets out how AI systems and...more

Health Care Organizations and Cloud Service Providers Receive Guidance on Cloud Security Measures

The Situation: The health care sector is currently going through a digital transformation phase with the promise of achieving improved patient care and higher efficiency—and the implementation of cloud-based services is a...more

Jones Day Global Privacy & Cybersecurity Update | Vol. 27

United States - Regulatory—Policy, Best Practices, and Standard - NIST Unveils Draft Guidance to Protect Critical Infrastructure - On October 22, 2020, the National Institute of Standards and Technology ("NIST")...more

Strong Customer Authentication in the United States: When, Not If

The Situation: Although the deadline keeps getting extended, e-commerce merchants and payment processors across the European Union are racing to implement the strong customer authentication ("SCA") requirements of the Revised...more

No-Deal Brexit—Preventing Disruption to Data Transfers

The Situation: The European Union and United Kingdom have both warned companies to prepare for a no-deal Brexit. The Result: There is a real possibility that the Brexit Implementation Period will end on 31 December 2020...more

Jones Day Global Privacy & Cybersecurity Update | Vol. 26

UNITED STATES - Regulatory—Policy, Best Practices, and Standards - NIST Releases Revision to Security Standard - On September 23, the National Institute of Standards and Technology ("NIST") released Revision 5 to...more

Ensuring International Data Flows after Schrems II

The Situation: After the invalidation of the EU-U.S. Privacy Shield by the Court of Justice of the European Union ("CJEU"), the conditions under which international data may flow from the European Union continue to remain...more

End of the EU's Data Retention Saga? CJEU Clarifies Conditions for State Surveillance Regimes

The Situation: On October 6, 2020, the Court of Justice of the European Union ("CJEU") held that the national security laws of the United Kingdom, France, and Belgium, which each require that providers of electronic...more

44 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide